Description
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Coherence accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).
Published: 2026-07-21
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability resides in the core component of Oracle Coherence, part of Oracle Fusion Middleware. An unauthenticated attacker with network access to the HTTP interface can trigger the flaw, resulting in read access to a subset of data that the application holds. This impacts the confidentiality of stored information while leaving integrity and availability untouched. The weakness corresponds to improper access control and information exposure of data resources.

Affected Systems

Oracle Coherence versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0 are affected. The vulnerability is present in the core component of the Oracle Fusion Middleware stack.

Risk and Exploitability

The CVSS base score of 5.3 indicates a moderate risk, limited to confidentiality impact. The EPSS score of less than 1% suggests a low probability of real-world exploitation at this time. The vulnerability is not listed in the CISA KEV catalog. The attack vector is an unauthenticated HTTP request to the Coherence service, requiring no additional credentials.

Generated by OpenCVE AI on August 4, 2026 at 17:30 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Oracle Coherence to the latest patch released by Oracle for the affected versions.
  • Restrict network access to the Coherence HTTP endpoints, allowing only trusted hosts or VPN connections.
  • Enforce strict authorization controls within Coherence so that only authenticated users can access protected data.

Generated by OpenCVE AI on August 4, 2026 at 17:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Data Disclosure via Oracle Coherence Core Component

Thu, 30 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Data Disclosure via Oracle Coherence Core Component

Mon, 27 Jul 2026 14:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Information Disclosure in Oracle Coherence via HTTP
Weaknesses CWE-284

Fri, 24 Jul 2026 01:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Information Disclosure in Oracle Coherence via HTTP
Weaknesses CWE-284

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Coherence accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).
First Time appeared Oracle
Oracle coherence
CPEs cpe:2.3:a:oracle:coherence:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:coherence:14.1.1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:coherence:14.1.2.0.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:coherence:15.1.1.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle coherence
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

Oracle Coherence
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-23T19:23:49.187Z

Reserved: 2026-07-08T15:51:40.528Z

Link: CVE-2026-60283

cve-icon Vulnrichment

Updated: 2026-07-23T19:23:30.424Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T17:45:03Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor